Block Access to INternet to one IP Address in Juniper SSG20 + Monitoring Traffic,

Dear EE Experts

I want to block Internet Access to inly one IP Address on the network, but i want to be able to remote desktop from outside , i.e. the internet

Also Is there a way we can record the remote desktop session of the user who is logging on remotely

Thanks

LVL 2
mivbinfotechAsked:
Who is Participating?
 
SteveIT ManagerCommented:
Add a specific rule in the firewall to exclude the services you want to block

Add the rdp service into the rule
0
 
mivbinfotechAuthor Commented:
i want to block all services, it does not work, that way
0
 
mivbinfotechAuthor Commented:
I am making the entry as From Trust to Untrust

Source Address 192.168.1.5/24
Destination: Any
Service Any
Action Deny

And I put this above the default route for Any

But it denies all traffic from 192.168.1.0 range, is there anything i m doing wrong

0
The Firewall Audit Checklist

Preparing for a firewall audit today is almost impossible.
AlgoSec, together with some of the largest global organizations and auditors, has created a checklist to follow when preparing for your firewall audit. Simplify risk mitigation while staying compliant all of the time!

 
mivbinfotechAuthor Commented:
I have done this by defining the address 192.168.1.5/255.255.255.255
Thanks
0
 
kurtholm2004Commented:
I always suggest adding logging on all rules that are added so you can see what type of traffic is hitting that rule. Do you have the blocking of the out going the way you want it currently?

To do the rdp this could vary on a few things. What type of internet connection do you have? Is it a residential dsl or cable? Is it business class dsl, cable, T1 or so on? Do you have a dedicated IP or dynamic? Also what version of the ScreenOS are you running on the SSG20?
0
 
mivbinfotechAuthor Commented:
Actually I had enabled logging for the rule and figured i was missing on the syntax,,, i put..

0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.